Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk What breaks when organisations rely on SMS codes…
Governance, Ownership & Risk

What breaks when organisations rely on SMS codes and knowledge-based checks for identity assurance?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 26, 2026 Domain: Governance, Ownership & Risk

SMS codes and knowledge-based checks break down because they are easy to intercept, guess, or socially engineer, and they create poor user experience. They also provide limited evidence that the person is truly present at the point of transaction. In practice, they are better treated as low-assurance signals, not primary trust mechanisms.

Why This Matters for Security Teams

SMS codes and knowledge-based checks are still used as if they prove identity, but they mostly prove access to a phone number or memory of personal data. That is weak evidence for high-assurance identity because both factors can be intercepted, reset, guessed, or socially engineered. NIST SP 800-63 Digital Identity Guidelines makes the distinction between memorized secrets and stronger authenticators explicit, and current guidance increasingly treats SMS as lower assurance than phishing-resistant methods.

The practical risk is not limited to account takeover. Weak proofing also distorts downstream trust decisions, especially when identity assurance is used to unlock privileged actions, device enrollment, or recovery workflows. Once an attacker passes a low-friction check, they can often pivot into reset paths that are harder to monitor than the original login. NHIMG research on the Ultimate Guide to NHIs shows how identity risk compounds when assurance signals are reused without strong lifecycle controls, and the same pattern appears in human identity recovery flows.

In practice, many security teams discover these weaknesses only after a support-driven takeover or fraudulent reset has already been completed, rather than through intentional control testing.

How It Works in Practice

When organisations rely on SMS or knowledge-based checks, they are usually making a recovery or step-up decision with thin evidence. SMS codes can be redirected through SIM swap, call forwarding, malware, or compromised messaging accounts. Knowledge-based questions fail for a different reason: much of the answer space is public, leaked, or inferable from data brokers and social media. NIST SP 800-63 Digital Identity Guidelines recommends stronger authenticators and tighter proofing for higher assurance use cases, while eIDAS 2.0 reflects the broader shift toward verifiable, higher-integrity identity evidence.

Operationally, the safer pattern is to separate low-risk convenience checks from higher-risk assurance decisions:

  • Use SMS only as a fallback signal, not as the primary proof of identity for sensitive actions.
  • Prefer phishing-resistant factors, such as passkeys or hardware-backed authenticators, for authentication.
  • Treat KBA as a weak recovery aid and remove it from high-impact reset or enrollment flows.
  • Bind step-up checks to device, session, and transaction context so the control evaluates what is being requested, not just who claims to be there.
  • Review help desk scripts and exception paths, because attackers often target recovery channels instead of login pages.

NHIMG data shows the scale of identity fragility: only 5.7% of organisations have full visibility into their service accounts, and 80% of identity breaches involved compromised non-human identities such as service accounts and API keys. That is a reminder that weak assurance in one identity workflow often correlates with weak control elsewhere, which is why the 52 NHI Breaches Analysis is useful even for human identity governance teams.

These controls tend to break down when the environment depends on remote support, shared devices, number-porting risk, or legacy recovery workflows because the original proof of identity is no longer cryptographically bound to the requester.

Common Variations and Edge Cases

Tighter identity checks often increase user friction and support overhead, so organisations have to balance usability against assurance instead of treating every transaction the same. That tradeoff is real, but current guidance suggests it is better to apply stronger proofing only where the decision has meaningful consequence.

There is no universal standard for replacing SMS in every flow, but a few patterns are clear. For low-risk notifications, SMS may remain acceptable as a convenience channel. For account recovery, credential reset, payout changes, admin enrollment, or anything that can lead to privilege escalation, SMS and KBA are usually too weak on their own. The more sensitive the action, the more the verifier should rely on device binding, stronger authenticators, and audited recovery steps. NHIMG’s Top 10 NHI Issues research is a useful reminder that weak identity controls often fail at the edges first, especially where human process and automation meet.

Security teams should also watch for false confidence in multifactor setups that still include SMS as one factor. If the second factor is easily diverted, the overall assurance level may not be materially better than the first factor alone. For organisations modernising identity assurance, the goal is not simply to add more checks, but to replace brittle ones with stronger, context-aware evidence.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST AI RMF set the technical controls, while NIS2 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-633.1.3Defines authenticator assurance and why SMS/KBA are weak proofing signals.
NIST CSF 2.0PR.AA-01Identity proofing and authentication should reflect the sensitivity of the action.
NIST Zero Trust (SP 800-207)IDZero Trust depends on strong identity signals, not brittle knowledge-based checks.
NIST AI RMFGOVERNIdentity assurance decisions need accountable governance and documented risk tolerances.
NIS2Weak identity assurance can undermine operational resilience and incident prevention.

Classify identity assurance by transaction risk and require stronger controls for high-impact events.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org